Security Policy Enforcement for Removable Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a growing need for enhanced computer protection systems to prevent theft of confidential information and harm to computer equipment or files, as existing systems are inadequate in addressing the increasing number of computer threats.

Innovation Solution

A method and computer program product assess the security compliance state of a client computing facility by comparing its configuration information with a security policy, blocking communication with removable storage devices if out of compliance, including USB, serial, parallel, and Bluetooth ports, to prevent data leakage and external threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system blocks communication with removable storage devices when security compliance is violated, then data leakage and malware spread are prevented, but device functionality and user productivity are reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts security controls based on real-time compliance status. When a device is out of compliance, access to removable storage devices is blocked; when compliance is restored, access is automatically restored. This dynamic adaptation allows the system to maintain security without permanently reducing functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the security parameter (access permission) based on the compliance state. By monitoring compliance parameters such as antivirus updates, patch levels, and security configurations, the system modifies the access parameter to block or allow device connections accordingly.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the system continuously monitors security compliance state, then security protection is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a feedback loop where compliance status is continuously monitored and reported back to the security management system. This feedback mechanism enables automatic enforcement actions without requiring complex manual intervention or overly complicated monitoring architectures.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The monitored device performs self-assessment of its security compliance state by checking its own configuration, updates, and security settings. This self-service approach reduces the complexity of centralized monitoring while maintaining effective security oversight.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9015789B2Computer security lock down methods
Publication Date: 2015.04.21 SOPHOS LTD
  • US9015789B2 patent drawing
  • US9015789B2 patent drawing
  • US9015789B2 patent drawing

AI summary

Embodiments of the present invention extend the enforcement of computer security policies by blocking device access as well as network access. In some embodiments, communications with external devices are blocked upon discovery that some aspect of the client computing facility is out of compliance vis-à-vis a security policy.